ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code.

“Attackers compromised the vendor’s build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels,” Wordfence said in an analysis

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI Boosts Research Careers but Flattens Scientific Discovery

AI Boosts Research Careers but Flattens Scientific Discovery Source: Hacker News

We don’t use AI in any of our design or production processes

We don’t use AI in any of our design or production processes Source: Hacker News

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source